Zhouyi Divination

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The `SKILL.md` file contains direct instructions for the OpenClaw AI agent to perform file system operations. Specifically, it instructs the agent to read a local file (`/Users/taisenzhuang/.openclaw/workspace/zhouyi-divination/mingzhu.md`) containing sensitive user astrological data, and to automatically save generated reports to a user's iCloud directory (`~/Library/Mobile Documents/com~apple~CloudDocs/Documents/OpenClaw/报告/运势/`). While these actions align with the skill's stated purpose, direct file I/O instructions via prompt injection represent a risky capability and potential vulnerability surface for an AI agent, even without clear evidence of malicious intent like data exfiltration to external servers or backdoor installation.